
SolarWinds Orion: Reverse Engineering and Additional Findings
On Wednesday, December 16, the RedDrip Team from QiAnXin Technology released their discoveries (tweet, github) regarding the random subdomains associated with the SUNBURST malware which was present in the SolarWinds Orion compromise.
In studying queries performed by the malware, Hakk.gg has uncovered additional details about how the Domain Generation